Skip to content

[GHSA-2w8x-224x-785m] sjcl is missing point-on-curve validation in sjcl.ecc.basicKey.publicKey#7225

Merged
advisory-database[bot] merged 1 commit intogithub:wmorland/advisory-improvement-7225from
wmorland:wmorland-GHSA-2w8x-224x-785m
Mar 25, 2026
Merged

[GHSA-2w8x-224x-785m] sjcl is missing point-on-curve validation in sjcl.ecc.basicKey.publicKey#7225
advisory-database[bot] merged 1 commit intogithub:wmorland/advisory-improvement-7225from
wmorland:wmorland-GHSA-2w8x-224x-785m

Conversation

@wmorland
Copy link

Updates

  • Updates modified timestamp
  • Adds fixed version to affected ranges
  • Adds fix commit url to references

Comments
Adding patched version 1.0.9 https://github.com/bitwiseshiftleft/sjcl?tab=readme-ov-file#security-advisories

@wmorland wmorland force-pushed the wmorland-GHSA-2w8x-224x-785m branch from cd38666 to e698ac6 Compare March 24, 2026 12:20
@github-actions github-actions bot changed the base branch from main to wmorland/advisory-improvement-7225 March 24, 2026 12:21
@advisory-database advisory-database bot merged commit 257af54 into github:wmorland/advisory-improvement-7225 Mar 25, 2026
2 checks passed
@advisory-database
Copy link
Contributor

Hi @wmorland! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@wmorland wmorland deleted the wmorland-GHSA-2w8x-224x-785m branch March 25, 2026 14:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant